Search

Found 14,238 results in 601ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-33199 unknown FIX slesdebian debian 3y ago Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a pan…
CVE-2023-32697 unknown FIX debian debian 3y ago Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
CVE-2023-32409 unknown 1.5 KEVFIX debian debian 3y ago Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impa…
CVE-2023-29159 unknown FIX debian debian 3y ago Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
CVE-2023-53160 unknown FIX slesdebian debian 3y ago The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVE-2023-32082 unknown FIX debian debian sles 3y ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease wh…
CVE-2016-3427 unknown 1.5 KEVFIX slesdebian debian 3y ago Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions …
CVE-2014-0196 unknown 2.5 KEVEXPFIX debian debian 3y ago Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with l…
CVE-2023-31141 unknown debian debian 3y ago OpenSearch issue with fine-grained access control during extremely rare race conditions
CVE-2023-30551 unknown FIX slesdebian debian 3y ago Rekor is an open source software supply chain transparency log. Rekor prior to version 1.1.1 may crash due to out of memory (OOM) conditions caused by reading archive metadata files into memory witho…
CVE-2023-22665 unknown FIX debian debian 3y ago Arbitrary javascript injection in Apache Jena
CVE-2023-2136 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2023-1892 unknown FIX debian debian 3y ago Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.
CVE-2023-29197 unknown FIX debian debian 3y ago guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names a…
CVE-2023-26048 unknown FIX slesdebian debian 3y ago OutOfMemoryError for large multipart without filename in Eclipse Jetty
CVE-2023-26049 unknown FIX slesdebian debian 3y ago Eclipse Jetty's cookie parsing of quoted values can exfiltrate values from other cookies
CVE-2023-2033 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2023-20863 unknown debian debian 3y ago Spring Framework vulnerable to denial of service
CVE-2023-28840 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28841 unknown FIX debian debian sles 3y ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon componen…
CVE-2023-28842 unknown FIX debian debian sles 3y ago Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon compone…
CVE-2021-28235 unknown FIX slesdebian debian 3y ago Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVE-2022-3038 unknown 1.5 KEVFIX debian debian 3y ago Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2023-20860 unknown debian debian 3y ago Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVE-2023-28628 unknown debian debian 3y ago lambdaisland/uri `authority-regex` returns the wrong authority
CVE-2023-20861 unknown debian debian 3y ago Spring Framework vulnerable to denial of service via specially crafted SpEL expression
CVE-2023-1370 unknown FIX debian debian 3y ago json-smart Uncontrolled Recursion vulnerability
CVE-2023-1436 unknown FIX slesdebian debian 3y ago Jettison vulnerable to infinite recursion
CVE-2021-46877 unknown FIX slesdebian debian 3y ago jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
CVE-2023-24535 unknown FIX debian debian 3y ago Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a…
CVE-2023-26464 unknown FIX debian debian 3y ago Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
CVE-2023-27476 unknown FIX slesdebian debian 3y ago OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lx…
CVE-2022-41918 unknown FIX debian debian 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown FIX slesdebian debian 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-4492 unknown FIX debian debian 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2023-26302 unknown FIX slesdebian debian 3y ago Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.
CVE-2023-26303 unknown FIX slesdebian debian 3y ago Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
CVE-2022-46169 unknown 2.5 KEVEXPFIX debian debian sles 3y ago Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CVE-2023-30798 unknown FIX debian debian 3y ago There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause e…
CVE-2022-24894 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown FIX debian debian 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-47951 unknown FIX debian debian sles 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2023-23613 unknown debian debian 3y ago Field-level security issue with .keyword fields in OpenSearch
CVE-2023-23612 unknown debian debian 3y ago Issue with whitespace in JWT roles in OpenSearch
CVE-2023-22742 unknown FIX slesdebian debian 3y ago libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versio…
CVE-2022-47950 unknown FIX slesdebian debian 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown FIX debian debian 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2023-22602 unknown debian debian 3y ago Apache Shiro Interpretation Conflict vulnerability
CVE-2022-41721 unknown FIX debian debian 3y ago A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from th…
CVE-2022-46176 unknown FIX debian debian sles 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2023-22899 unknown FIX debian debian 3y ago Zip4j Origin Validation Error
CVE-2023-22466 unknown FIX debian debian 4y ago Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` …
CVE-2022-45143 unknown FIX slesdebian debian 4y ago The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from use…
CVE-2022-40151 unknown slesdebian debian 4y ago XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow
CVE-2022-41966 unknown FIX slesdebian debian 4y ago XStream can cause Denial of Service via stack overflow
CVE-2022-45693 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-45685 unknown FIX slesdebian debian 4y ago Jettison Out-of-bounds Write vulnerability
CVE-2022-41915 unknown FIX slesdebian debian 4y ago Netty vulnerable to HTTP Response splitting from assigning header value iterator
CVE-2022-41881 unknown FIX slesdebian debian 4y ago HAProxyMessageDecoder Stack Exhaustion DoS
CVE-2022-3510 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-3509 unknown FIX slesdebian debian 4y ago Protobuf Java vulnerable to Uncontrolled Resource Consumption
CVE-2022-23491 unknown FIX slesdebian debian 4y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates fro…
CVE-2022-44900 unknown FIX debian debian 4y ago A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z fil…
CVE-2022-4262 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-37533 unknown FIX slesdebian debian 4y ago Apache Commons Net vulnerable to information leakage via malicious server
CVE-2022-46146 unknown FIX slesdebian debian 4y ago Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypa…
CVE-2022-46149 unknown FIX debian debian sles 4y ago Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementatio…
CVE-2022-45907 unknown FIX debian debian 4y ago In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-4135 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML p…
CVE-2022-4065 unknown FIX slesdebian debian 4y ago TestNG is vulnerable to Path Traversal
CVE-2022-45136 unknown FIX debian debian 4y ago Apache Jena vulnerable to Deserialization of Untrusted Data
CVE-2022-41854 unknown FIX slesdebian debian 4y ago Snakeyaml vulnerable to Stack overflow leading to denial of service
CVE-2022-42964 unknown FIX debian debian 4y ago An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method
CVE-2022-42252 unknown FIX slesdebian debian 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f…
CVE-2022-3723 unknown 1.5 KEVFIX debian debian 4y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2022-39327 unknown FIX debian debian sles 4y ago Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting ma…
CVE-2022-42890 unknown FIX debian debian sles 4y ago Untrusted code execution in Apache XML Graphics Batik
CVE-2022-41704 unknown FIX debian debian sles 4y ago Apache XML Graphics Batik vulnerable to code execution via SVG.
CVE-2021-3493 unknown 2.5 KEVEXPFIX slesdebian debian 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2022-42969 unknown slesdebian debian 4y ago Withdrawn Advisory: ReDoS in py library when used with subversion
CVE-2022-41404 unknown FIX debian debian 4y ago org.ini4j allows attackers to cause a Denial of Service (DoS)
CVE-2022-40664 unknown debian debian 4y ago Apache Shiro Authentication Bypass vulnerability
CVE-2020-15115 unknown FIX slesdebian debian 4y ago etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess …
CVE-2020-15112 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are b…
CVE-2020-15106 unknown FIX slesdebian debian 4y ago In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on …
CVE-2022-39237 unknown FIX debian debian 4y ago syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) us…
CVE-2022-41853 unknown FIX slesdebian debian 4y ago HyperSQL DataBase vulnerable to remote code execution when processing untrusted input
CVE-2022-3171 unknown FIX slesdebian debian 4y ago protobuf-java has a potential Denial of Service issue
CVE-2021-43980 unknown FIX slesdebian debian 4y ago The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in …
CVE-2022-39261 unknown FIX debian debian 4y ago Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a us…
CVE-2022-36944 unknown FIX slesdebian debian 4y ago Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
CVE-2022-40146 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38648 unknown FIX debian debian sles 4y ago Apache Batik vulnerable to Server-Side Request Forgery
CVE-2022-38398 unknown FIX debian debian sles 4y ago Apache Batik Server-Side Request Forgery
CVE-2022-40152 unknown slesdebian debian 4y ago Denial of Service due to parser crash
CVE-2022-40150 unknown FIX slesdebian debian 4y ago Jettison memory exhaustion
CVE-2022-40149 unknown FIX debian debian 4y ago Jettison parser crash by stackoverflow
CVE-2022-36109 unknown FIX debian debian sles 4y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has di…
CVE-2022-36056 unknown FIX debian debian 4y ago Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-bl…
CVE-2022-36113 unknown FIX debian debian sles 4y ago Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it…